
Store Networks
Part of Retail store networks
Verify shopper Wi-Fi isolation from store systems
Use a store-specific access-path list and witnessed checks to accept, revise or hold shopper Wi-Fi isolation from tills, staff and payment systems.
Before accepting an installed store network, test shopper Wi-Fi against the store’s tills, payment terminals, staff handhelds, administration interfaces and each approved supplier route. A separate Wi-Fi name does not show whether those paths are reachable; acceptance needs a store-specific diagram, rule list and witnessed results.
Map the store's actual paths
Use the final diagram and rule list to identify the installed network-segmentation control and where it separates shopper Wi-Fi from business systems. Match the documents to the installed configuration version; a separate Wi-Fi name alone is not evidence of isolation.
Draw the access point, gateway, business systems and any remote-support connection. Label each device group with the task it must perform. A stockroom handheld might need the inventory service, but not the router’s administration page.
A till might need a receipt printer. The payment terminal’s permitted destinations depend on the payment provider’s design. Do not infer routes just because devices share a counter.
Give the technician a short acceptance list:
| Starting point | Required path to confirm | Path that should be blocked |
|---|---|---|
| Shopper phone on guest Wi-Fi | Customer internet access | Till, stockroom printer, staff service and network administration |
| Till and approved peripherals | The sales and printing paths in the store design | Unneeded access to other device groups |
| Staff handheld | Its assigned stock or order service | Payment equipment and network administration unless expressly required |
| Supplier support connection | The named service, destination and time window approved by the retailer | General access to the store network |
For this store, use the actual destinations and permitted tasks from its design rather than leaving the table as generic labels. For example, test from a device on shopper Wi-Fi to the store’s named till destination and router administration interface; both should be blocked.
Treat the table as a starting specification, not evidence that a particular store has those controls.
Witness the acceptance checks
With the store’s authorisation, connect a test device to shopper Wi-Fi and confirm its intended internet access. Then test each named business destination and administration interface using the relevant service protocol; a failed ping alone does not prove other routes are closed.
For each path, record the test device, network, actual named destination, expected permitted or blocked result, observed result and configuration version. Keep the final diagram and rule list with the record, and identify the person who accepts any exception.
Have a staff user confirm the approved handheld and till tasks still work. Have the payment provider or installer verify payment paths under the agreed design, and test the supplier connection only against its named approved service, destination and time window.
Before signing off, compare the witnessed results with the store’s diagram and rule list. Accept if required tasks work and denied paths are demonstrated; request a change and retest if an approved task fails or shopper Wi-Fi reaches a business service. Hold acceptance if the supplier route, payment path or evidence is unclear.
A captive portal, hidden Wi-Fi name or shared password does not substitute for those checks.
Keep payment and supplier boundaries explicit
If segmentation is used to reduce PCI DSS scope, the PCI Security Standards Council says an assessor must verify that the controls are effective and working as intended. Guest Wi-Fi separation alone cannot establish the store’s scope or compliance; confirm the actual card-data environment with the acquirer or qualified payment adviser.
When you add a new till, kiosk, printer, access point or supplier connection, update the path drawing and repeat the affected checks. Tie supplier access to a named source, destination, purpose and owner, so a later support request does not silently broaden the route.
Key Compliance Requirements for Network Segmentation
- PCI DSS Scope Reduction Requirement
- Must be verified by assessor – isolation alone is not sufficient
- Australian Cyber Security Framework Guidance
- Network segmentation and segregation recommended under ISM guidelines
- System Hardening Standard
- Implementing network segmentation is a key control for securing systems
- Post-Change Verification
- Update path drawings and retest after adding new devices or supplier connections



